nix-installer icon indicating copy to clipboard operation
nix-installer copied to clipboard

Verify integrity of installer binaries in nix-installer.sh

Open andrewhamon opened this issue 1 year ago • 2 comments
trafficstars

It appears that nix-installer.sh does not perform any integrity checking of the binaries it downloads. This is surprising and concerning - it seems it takes care to use secure TLS ciphers - why bother when it would be more secure to bake in the expected shasums?

andrewhamon avatar Jul 19 '24 18:07 andrewhamon